Trouble with group policy probably due to SYSVOL DFRS replication issues

Roberto 646 Reputation points
2021-04-22T13:37:24.323+00:00

Hello.

It's some time I notice clients apply some group policy after a high delay and at times they don't even get applied. In particular a policy that adds Shared Printers.
Yesterday I noticed that three (out of six) DCs are always in status "replication in progress"
90326-20210421asv-118synchro-error.jpg

Could somebody please help me out?

Thank you and best regards.
Roberto

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,724 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,081 questions
{count} votes

Accepted answer
  1. Roberto 646 Reputation points
    2021-05-06T11:30:51.113+00:00

    Hi @Daisy Zhou
    Hi @Dave Patrick

    Sorry for getting back to you late.

    Unfortunately I have not understood what was the cause of this problem.

    Anyways, here's how I solved it.
    On the PDC:

    1) copy/paste of the policies (about 10) that were not in sync
    2) deleted the original policies and renamed the new to the original name

    Now all policies are in sync.

    Thank you and best regards.
    Roberto


4 additional answers

Sort by: Most helpful
  1. Dave Patrick 426K Reputation points MVP
    2021-04-22T14:33:18.253+00:00

    You can try a non authoritative synchronization
    https://support.microsoft.com/en-us/help/2218556/how-to-force-an-authoritative-and-non-authoritative-synchronization-fo

    or simply move roles off, demote, reboot, promo it again if tombstoned. The event log should have more details.

    --please don't forget to Accept as answer if the reply is helpful--


  2. Daisy Zhou 18,701 Reputation points Microsoft Vendor
    2021-04-23T02:23:09.207+00:00

    Hello @Roberto ,

    Thank you for posting here.

    Based on the description, I understand you have one domain with five DCs.

    Before we troubleshoot SYSVOL DFSR replication issue, we must check whether AD replication between the five DCs works fine.

    If there is any issue about AD replication between all the five DCs, we should fix AD replication issue first, then trouble SYSVOL DFSR replication issue.

    If AD replication between all the five DCs works fine, then if there is indeed SYSVOL DFSR replication issue, we can troubleshoot SYSVOL DFSR replication issue.

    Check AD replication status:

    1.On the PDC, run the command below to force AD replication immediately and check if there is any error message.

    repadmin /syncall /AdeP

    2.On the PDC, run the three commands below to check there is any error message in the result.

    repadmin /showrepl >c:\rep1.txt

    repadmin /replsum >c:\rep2.txt

    repadmin /showrepl * /csv >c:\repsum.csv

    If all the results of the four commands above are OK without any error message, it means AD replication in your AD environment is OK.

    Then check SYSVOL DFSR replication issue:

    1.On all DCs, we can check if the number of the items under C:\Windows\SYSVOL\domain\Policies is the same or not.

    90544-it1.png

    2.If the number of the items under C:\Windows\SYSVOL\domain\Policies on the three DC you mentioned is not the same as baseline DC (SV-102-DC).

    Tip: the number of the items under C:\Windows\SYSVOL\domain\Policies is the largest on baseline DC.

    3.It means SYSVOL DFSR replication on the three DCs is not in sync.

    Should you have any question or concern, please feel free to let us know.

    Best Regards,
    Daisy Zhou

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.


  3. Dave Patrick 426K Reputation points MVP
    2021-04-26T17:53:36.653+00:00

    You can try a non authoritative synchronization
    https://support.microsoft.com/en-us/help/2218556/how-to-force-an-authoritative-and-non-authoritative-synchronization-fo

    or simply move roles off, demote, reboot, promo it again.

    --please don't forget to Accept as answer if the reply is helpful--


  4. Daisy Zhou 18,701 Reputation points Microsoft Vendor
    2021-04-27T01:12:28.37+00:00

    Hello @Roberto ,

    I am sorry for the late reply.

    Thank you so much for your update.

    And from the information you have checked and provided, it seems or I can see:

    1.The AD replication in your domain works fine
    2.The SYSVOL folder is synchronized (the number of items in the same path on all DCs is the same--157).

    Now based on the error message, we can compare the permissions of one GPO on baseline DC (SV-102-DC) and another DC (sv-108-dc)

    91494-gpo1.png

    1.Find the GPO with the following GUID on both DC.
    91496-gpo1.png

    2.Right click this GPO and select Properties.
    91495-g1.png

    3.Security tab and Advanced button and compare "Permission entries".
    91462-g2.png

    Should you have any question or concern, please feel free to let us know.

    Best Regards,
    Daisy Zhou

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments